Bitcoin emergency recovery plan

An emergency recovery plan is an operational template for the first hours and days after a wallet failure, backup problem, suspected exposure, or owner unavailability.

Keep the plan non-secret. It should identify roles, components, trusted workflows, and action order without containing the seed phrase, passphrase, device PIN, or complete secret-location map.

What activates the plan

  • The hardware wallet is lost, stolen, damaged, or unavailable.
  • The seed backup is missing, damaged, unreadable, or fails verification.
  • Someone may have viewed, copied, photographed, or digitized the seed.
  • The owner is incapacitated, missing, or deceased.
  • A storage location, trusted person, institution, or passphrase path becomes unavailable.
  • A wallet migration or urgent replacement is required.

The first five rules

  1. Preserve every working access path. Do not reset, wipe, sell, or discard a functioning wallet.
  2. Do not enter the seed into a website, AI tool, cloud document, email, phone note, or unsolicited recovery service.
  3. Identify whether the problem is loss, damage, exposure, owner unavailability, or a combination.
  4. Confirm the intended wallet before moving funds or retiring old components.
  5. Use only the authority, people, and workflows defined by the plan.

Emergency action order

StageAction
1. StabilizePreserve device access, backups, logs, seals, and relevant non-secret information.
2. ClassifyDetermine what remains available and whether compromise is possible.
3. AuthorizeConfirm who may act and which professional or technical helper may participate.
4. Recover or replaceUse the legitimate wallet workflow, or create a new verified wallet when the old seed is exposed.
5. ConfirmMatch the expected wallet and exact passphrase branch before relying on the result.
6. Migrate when requiredMove away from a compromised or unrecoverable setup only after the replacement path is verified.
7. Retire and documentRetire obsolete components, correct the failure, and record a non-secret incident result.

Copy-and-use emergency template

BITCOIN EMERGENCY RECOVERY PLAN

Plan owner / wallet ID:
Version date:
Authorized person or role:
Activation events:

CURRENT SYSTEM
- Wallet model or setup:
- Active backup ID:
- Recovery format:
- Passphrase: none / exists through separate path
- Expected-wallet confirmation method:
- Legitimate wallet documentation:
- Approved technical helper:
- Legal or fiduciary contact:

FIRST ACTIONS
1. Preserve working wallet access and all recovery components.
2. Do not expose the seed through an online or unsolicited workflow.
3. Classify the incident: device loss / backup loss / damage / exposure / owner unavailable.
4. Confirm authority and the correct wallet.
5. Follow the matching scenario branch below.

STOP CONDITIONS
- The seed is requested by a website, support agent, AI tool, or remote-access session.
- The wallet identity cannot be confirmed.
- A passphrase or share threshold is uncertain.
- The only functioning device would need to be reset.
- Legal authority is unclear.

AFTER RECOVERY
- Verify the active recovery path.
- Retire obsolete devices and backups only after verification.
- Correct the storage or process failure.
- Update family, inheritance, and emergency documents.

Scenario branches

Device lost or damaged, verified seed remains

Protect the seed, obtain a legitimate compatible recovery environment, restore through current official instructions, confirm the intended wallet, and replace the device if needed. Do not expose the seed to random software.

Seed backup lost, working wallet remains

Preserve the working wallet. Create a new wallet with a new seed, verify the new recovery path, then migrate through the legitimate wallet workflow. A new metal product cannot recreate the missing old seed.

Seed backup damaged or ambiguous

Do not guess while another working access path exists. Preserve the device and any reliable source record, verify what remains readable, and create a replacement before retiring the old material.

Seed may be exposed

Treat credible complete-seed exposure as a compromise. Create a new wallet with a new verified seed, migrate away from the exposed wallet, and retire every old copy. Follow the exposure-response guide.

Owner unavailable

Confirm the activation event, legal authority, family instructions, component map, and trusted recovery support. Do not let urgency bypass the authority boundary.

Test the plan without exposing secrets

At least one authorized person should be able to find the current plan, identify the scenario branches, locate the legitimate instructions and helpers, explain the expected-wallet confirmation method, and name the stop conditions.

Use the recovery drill for periodic rehearsal and the verification checklist for the physical backup result.

Review triggers

  • wallet, firmware, or recovery-format change;
  • new or changed passphrase;
  • move or storage-location change;
  • new trusted person, institution, lawyer, executor, or technical helper;
  • family or legal-document change;
  • damaged, lost, exposed, added, or retired recovery component;
  • completed recovery drill or incident.

Final operating rule

Preserve current control, classify the incident, confirm authority, use the legitimate recovery path, verify the intended wallet, and retire old components only after the replacement is proven.

Close the physical-backup gap after the plan is complete

The emergency plan should identify the active wallet, exact recovery format, passphrase status, authorized role, storage location, and verification workflow before a product is chosen. For a compact permanent backup, Trezor Keep Metal is our overall winner, but the variant must match the wallet's actual recovery format.

Official Trezor store affiliate link. We may earn a commission at no extra cost to you.

Frequently asked questions

Should the emergency plan contain the seed phrase?

No. It should contain roles, component IDs, trusted workflows, stop conditions, and action order. Keep wallet secrets in controlled recovery locations.

What is the first action after a hardware wallet breaks?

Preserve the device and every recovery component, determine whether a verified seed remains, and use current official recovery instructions. Do not reset or discard the device impulsively.

What changes when the seed may be exposed?

The problem becomes compromise rather than ordinary recovery. Create a new wallet with a new verified seed and migrate away from the exposed wallet.

Does a damaged backup require immediate guessing?

No. Preserve any working wallet access and reliable source record. Interpret or replace the damaged backup through a controlled process before retiring anything.

How often should the emergency plan be reviewed?

Review it after material wallet, passphrase, location, family, legal, trusted-person, backup, or incident changes, and after recovery drills.

Does an emergency plan replace inheritance planning?

No. The emergency plan defines operational action. Inheritance planning defines authority, roles, and intended succession.